GRC (Governance, Risk and Compliance) Lead

Client 1

Canberra

On-site

AUD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Defence projects
Secure environments
Career growth
Industry leaders
Job stability

Job summary

Client 1, a leading Australian technology organisation delivering capabilities to Defence and Government customers, seeks a GRC Lead to drive governance, risk and compliance across a complex tech environment in Canberra.

Reporting to cyber security leadership, you will manage A&A processes, develop policies, and engage with stakeholders to strengthen the organisation's cyber posture while ensuring accreditation and regulatory obligations are met.

Qualifications

  • Proven experience in cyber governance, risk and compliance.
  • Knowledge of Assessment and Authorisation frameworks and methodologies.
  • Experience in developing security documentation and accreditation artefacts.
  • Familiarity with the DSPF and ISM/Essential Eight controls.
  • Ability to engage with Defence and government stakeholders.

Responsibilities

  • Lead cyber governance, risk and compliance activities.
  • Drive cyber security risk assessment and risk treatment.
  • Manage Assessment and Authorisation (A&A) processes.
  • Develop and maintain cyber security policies and procedures.
  • Support accreditation activities for internal and external stakeholders.
  • Collaborate with technology, operations and security teams to improve outcomes.
  • Contribute to security architectures and controls implementations.
  • Maintain cyber risk registers and provide governance reporting.
  • Engage with government agencies, Defence bodies and vendors as required.

Skills

GRC fundamentals
Assessment & Authorisation
Policies & risk docs
DSPF knowledge
ISM/Essential Eight
Stakeholder engagement
MITRE ATT&CK familiarity
Defence environment experience

Education

CISSP
CISM
CRISC
ISO 27001 Lead Implementer/Auditor
Other cyber security certs

Job description

Role Title

GRC (Governance, Risk and Compliance) Lead

Location

Canberra, ACT

Working Arrangement

Permanent

Clearance Required

Active AGSVA TSPV required, NV2 may be considered with the willingness to uplift to TSPV.

Company Overview

Join a highly regarded Australian technology organisation delivering advanced capability to Defence and Government customers. Operating at the forefront of national security, the organisation is renowned for developing complex, mission-critical systems that directly contribute to Australia's defence capability.

You’ll be joining a high-performing cyber security function where governance, risk and compliance play a critical role in protecting sensitive environments and enabling the delivery of cutting-edge technology programs. This is an opportunity to have genuine influence, work alongside respected cyber professionals, and contribute to projects of national importance.

Job Description

We are seeking an experienced Governance, Risk and Compliance Cyber Lead to drive cyber governance, risk management, compliance and system authorisation activities across a complex technology environment.

Reporting into cyber security leadership, you will act as a trusted advisor to stakeholders, ensuring systems meet cyber security requirements, regulatory obligations and accreditation standards. You will lead Assessment and Authorisation activities, support cyber risk management processes and contribute to strengthening the organisation's overall cyber security posture.

Duties and Responsibilities
  • Lead cyber governance, risk and compliance activities across the organisation.
  • Drive cyber security risk assessment and risk treatment activities.
  • Manage and support system Assessment and Authorisation (A&A) processes.
  • Develop and maintain cyber security policies, procedures and supporting documentation.
  • Support accreditation and assurance activities for internal and external stakeholders.
  • Work closely with technology, operations and security teams to improve cyber security outcomes.
  • Contribute to the implementation of security architectures and cyber security controls.
  • Maintain cyber risk registers and support enterprise risk management activities.
  • Provide governance reporting, metrics and insights to leadership.
  • Engage with government agencies, authorisation bodies, Defence stakeholders and vendors as required.
Education / Certifications Required

Desirable certifications include:

  • CISSP
  • CISM
  • CRISC
  • ISO 27001 Lead Implementer or Lead Auditor
  • Other relevant cyber security, governance or risk management certifications
Knowledge / Skills Required
  • Demonstrated experience within Cyber Governance, Risk and Compliance.
  • Strong understanding of Assessment and Authorisation frameworks and methodologies.
  • Experience developing security documentation, including policies, procedures, risk assessments and accreditation artefacts.
  • Knowledge of the Defence Security Principles Framework (DSPF).
  • Strong understanding of the Information Security Manual (ISM) and Essential Eight.
  • Experience conducting cyber security risk assessments and managing remediation activities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to work with both technical and non-technical audiences.
  • Strong analytical and critical thinking capabilities.
  • Knowledge of the MITRE ATT&CK Framework is highly regarded.
  • Experience supporting Defence-accredited environments will be highly regarded.
Employment Benefits
  • Opportunity to work on nationally significant Defence and Government programs.
  • Exposure to complex and highly secure technology environments.
  • Career growth within a mature and respected cyber security function.
  • Work alongside experienced industry leaders and subject matter experts.
  • Long-term career stability with a growing Australian organisation.
  • Competitive remuneration package.
Diversity and Inclusion

We are committed to creating an inclusive workplace where diversity is valued and respected. We encourage applications from people of all backgrounds, cultures, identities, abilities and experiences.

Veterans

Veterans and ex-serving Australian Defence Force personnel are strongly encouraged to apply. Your experience, leadership and understanding of complex environments are highly valued.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Consultant
GRC Consultant

Cleared Recruitment • Canberra

On-site
AUD 120,000 - 170,000
GRC Specialist
GRC Specialist

Client 1 • Canberra

On-site
AUD 110,000 - 150,000
14% superannuation
6 weeks annual leave
Professional development
+2
GRC Specialist
GRC Specialist

Cleared Recruitment • Canberra

On-site
AUD 110,000 - 150,000
14% superannuation
6 weeks annual leave
Mentoring and development
+2
Cyber GRC Analyst
Cyber GRC Analyst

Client 1 • City of Brisbane

On-site
AUD 110,000 - 160,000
Private health insurance
Generous annual leave entitlements
Annual incentive programme
+5
Cyber GRC Lead - National Security, Canberra (Active TSPV)
Cyber GRC Lead - National Security, Canberra (Active TSPV)

Client 1 • Canberra

On-site
AUD 150,000 - 210,000
Defence projects
Secure environments
Career growth
+2
Cyber Security GRC
Cyber Security GRC

C4I Solutions Pty • Sydney

On-site
AUD 140,000 - 190,000
Cyber GRC Manager (PSTV Cleared)
Cyber GRC Manager (PSTV Cleared)

Sirius. • Canberra

On-site
AUD 120,000 - 160,000
Defence Cyber GRC Specialist – Governance & ATO
Defence Cyber GRC Specialist – Governance & ATO

C4I Solutions Pty • Sydney

On-site
AUD 100,000 - 130,000
Long Service Leave @ 7 years
Health & wellbeing allowance
First year leave (5 days)
+5
Cyber Security GRC
Cyber Security GRC

c4isolutions • Sydney

On-site
AUD 140,000 - 200,000
Long Service Leave
Health & wellbeing allowance
First year leave
+6
Defence Cyber Security GRC Specialist
Defence Cyber Security GRC Specialist

C4I Solutions Pty • Sydney

Hybrid
AUD 140,000 - 190,000